Inclusion of Sensitive Information in Log Files in go-getter - CVE-2022-29810
Published: June 27, 2022 / Updated: June 28, 2022
Vulnerability identifier: #VU64700
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29810
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to go-getter library can write SSH credentials into its log file. A local user with access to log files can read credentials in clear text, which may lead to privilege escalation or account takeover.
Affected software
go-getter
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Watson AIOps
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Watson AIOps
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
How to mitigate CVE-2022-29810
Install updates from vendor's website.
go-getter - update to 1.5.11
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.11, 2.4.5, 2.5.0
IBM Cloud Pak for Watson AIOps - update to 4.4.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
Red Hat OpenShift Container Platform - update to 4.11.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.11, 2.4.5, 2.5.0
IBM Cloud Pak for Watson AIOps - update to 4.4.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
Red Hat OpenShift Container Platform - update to 4.11.0
External References
Related Security Bulletins
- Privilege escalation in HashiCorp go-getter
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.3
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2